Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2019-20907
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.003
EPSS Ranking
54.5%
CVSS Severity
CVSS v3 Score
7.5
CVSS v2 Score
5.0
References
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00051.html
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00052.html
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00053.html
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00056.html
https://bugs.python.org/issue39017
https://github.com/python/cpython/pull/21454
https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html
https://lists.debian.org/debian-lts-announce/2020/11/msg00032.html
https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36XI3EEQNMHGOZEI63Y7UV6XZRELYEAU/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CAXHCY4V3LPAAJOBCJ26ISZ4NUXQXTUZ/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNHPQGSP2YM3JAUD2VAMPXTIUQTZ2M2U/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CTUNTBJ3POHONQOTLEZC46POCIYYTAKZ/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE4O3PNDNNOMSKHNUKZKD3NGHIFUFDPX/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NTBKKOLFFNHG6CM4ACDX4APHSD5ZX5N4/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PDKKRXLNVXRF6VGERZSR3OMQR5D5QI6I/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TOGKLGTXZLHQQFBVCAPSUDA6DOOJFNRY/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3TALOUBYU2MQD4BPLRTDQUMBKGCAXUA/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V53P2YOLEQH4J7S5QHXMKMZYFTVVMTMO/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VT4AF72TJ2XNIKCR4WEBR7URBJJ4YZRD/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILCHHTNLH4GG4GSQBX2MZRKZBXOLCKE/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YSL3XWVDMSMKO23HR74AJQ6VEM3C2NTS/
https://security.gentoo.org/glsa/202008-01
https://security.netapp.com/advisory/ntap-20200731-0002/
https://usn.ubuntu.com/4428-1/
https://www.oracle.com/security-alerts/cpujan2021.html
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00051.html
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00052.html
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00053.html
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00056.html
https://bugs.python.org/issue39017
https://github.com/python/cpython/pull/21454
https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html
https://lists.debian.org/debian-lts-announce/2020/11/msg00032.html
https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36XI3EEQNMHGOZEI63Y7UV6XZRELYEAU/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CAXHCY4V3LPAAJOBCJ26ISZ4NUXQXTUZ/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNHPQGSP2YM3JAUD2VAMPXTIUQTZ2M2U/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CTUNTBJ3POHONQOTLEZC46POCIYYTAKZ/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE4O3PNDNNOMSKHNUKZKD3NGHIFUFDPX/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NTBKKOLFFNHG6CM4ACDX4APHSD5ZX5N4/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PDKKRXLNVXRF6VGERZSR3OMQR5D5QI6I/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TOGKLGTXZLHQQFBVCAPSUDA6DOOJFNRY/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3TALOUBYU2MQD4BPLRTDQUMBKGCAXUA/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V53P2YOLEQH4J7S5QHXMKMZYFTVVMTMO/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VT4AF72TJ2XNIKCR4WEBR7URBJJ4YZRD/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILCHHTNLH4GG4GSQBX2MZRKZBXOLCKE/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YSL3XWVDMSMKO23HR74AJQ6VEM3C2NTS/
https://security.gentoo.org/glsa/202008-01
https://security.netapp.com/advisory/ntap-20200731-0002/
https://usn.ubuntu.com/4428-1/
https://www.oracle.com/security-alerts/cpujan2021.html
Products affected by CVE-2019-20907
Netapp
»
Active Iq Unified Manager
»
Version:
9.5
cpe:2.3:a:netapp:active_iq_unified_manager:9.5
Netapp
»
Active Iq Unified Manager
»
Version:
9.6
cpe:2.3:a:netapp:active_iq_unified_manager:9.6
Netapp
»
Cloud Volumes Ontap Mediator
»
Version:
N/A
cpe:2.3:a:netapp:cloud_volumes_ontap_mediator:-
Oracle
»
Zfs Storage Appliance Kit
»
Version:
8.8
cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8
Python
»
Python
»
Version:
3.5.0
cpe:2.3:a:python:python:3.5.0
Python
»
Python
»
Version:
3.5.1
cpe:2.3:a:python:python:3.5.1
Python
»
Python
»
Version:
3.5.2
cpe:2.3:a:python:python:3.5.2
Python
»
Python
»
Version:
3.5.3
cpe:2.3:a:python:python:3.5.3
Python
»
Python
»
Version:
3.5.4
cpe:2.3:a:python:python:3.5.4
Python
»
Python
»
Version:
3.5.5
cpe:2.3:a:python:python:3.5.5
Python
»
Python
»
Version:
3.5.6
cpe:2.3:a:python:python:3.5.6
Python
»
Python
»
Version:
3.5.7
cpe:2.3:a:python:python:3.5.7
Python
»
Python
»
Version:
3.5.8
cpe:2.3:a:python:python:3.5.8
Python
»
Python
»
Version:
3.5.9
cpe:2.3:a:python:python:3.5.9
Python
»
Python
»
Version:
3.6.0
cpe:2.3:a:python:python:3.6.0
Python
»
Python
»
Version:
3.6.1
cpe:2.3:a:python:python:3.6.1
Python
»
Python
»
Version:
3.6.10
cpe:2.3:a:python:python:3.6.10
Python
»
Python
»
Version:
3.6.11
cpe:2.3:a:python:python:3.6.11
Python
»
Python
»
Version:
3.6.2
cpe:2.3:a:python:python:3.6.2
Python
»
Python
»
Version:
3.6.3
cpe:2.3:a:python:python:3.6.3
Python
»
Python
»
Version:
3.6.4
cpe:2.3:a:python:python:3.6.4
Python
»
Python
»
Version:
3.6.5
cpe:2.3:a:python:python:3.6.5
Python
»
Python
»
Version:
3.6.6
cpe:2.3:a:python:python:3.6.6
Python
»
Python
»
Version:
3.6.7
cpe:2.3:a:python:python:3.6.7
Python
»
Python
»
Version:
3.6.8
cpe:2.3:a:python:python:3.6.8
Python
»
Python
»
Version:
3.6.9
cpe:2.3:a:python:python:3.6.9
Python
»
Python
»
Version:
3.7.0
cpe:2.3:a:python:python:3.7.0
Python
»
Python
»
Version:
3.7.1
cpe:2.3:a:python:python:3.7.1
Python
»
Python
»
Version:
3.7.2
cpe:2.3:a:python:python:3.7.2
Python
»
Python
»
Version:
3.7.3
cpe:2.3:a:python:python:3.7.3
Python
»
Python
»
Version:
3.7.4
cpe:2.3:a:python:python:3.7.4
Python
»
Python
»
Version:
3.7.5
cpe:2.3:a:python:python:3.7.5
Python
»
Python
»
Version:
3.7.6
cpe:2.3:a:python:python:3.7.6
Python
»
Python
»
Version:
3.7.7
cpe:2.3:a:python:python:3.7.7
Python
»
Python
»
Version:
3.7.8
cpe:2.3:a:python:python:3.7.8
Python
»
Python
»
Version:
3.8.0
cpe:2.3:a:python:python:3.8.0
Python
»
Python
»
Version:
3.8.0b1
cpe:2.3:a:python:python:3.8.0b1
Python
»
Python
»
Version:
3.8.1
cpe:2.3:a:python:python:3.8.1
Python
»
Python
»
Version:
3.8.2
cpe:2.3:a:python:python:3.8.2
Python
»
Python
»
Version:
3.8.3
cpe:2.3:a:python:python:3.8.3
Python
»
Python
»
Version:
3.8.4
cpe:2.3:a:python:python:3.8.4
Canonical
»
Ubuntu Linux
»
Version:
12.04
cpe:2.3:o:canonical:ubuntu_linux:12.04
Canonical
»
Ubuntu Linux
»
Version:
14.04
cpe:2.3:o:canonical:ubuntu_linux:14.04
Canonical
»
Ubuntu Linux
»
Version:
16.04
cpe:2.3:o:canonical:ubuntu_linux:16.04
Canonical
»
Ubuntu Linux
»
Version:
18.04
cpe:2.3:o:canonical:ubuntu_linux:18.04
Canonical
»
Ubuntu Linux
»
Version:
20.04
cpe:2.3:o:canonical:ubuntu_linux:20.04
Debian
»
Debian Linux
»
Version:
9.0
cpe:2.3:o:debian:debian_linux:9.0
Fedoraproject
»
Fedora
»
Version:
31
cpe:2.3:o:fedoraproject:fedora:31
Fedoraproject
»
Fedora
»
Version:
32
cpe:2.3:o:fedoraproject:fedora:32
Opensuse
»
Leap
»
Version:
15.1
cpe:2.3:o:opensuse:leap:15.1
Opensuse
»
Leap
»
Version:
15.2
cpe:2.3:o:opensuse:leap:15.2
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved